n8n-nodes-task-runner@1.0.0
Malicious code in n8n-nodes-task-runner (npm)
Analysis
n8n-nodes-task-runner@1.0.0 is a trojanized n8n community node package. On require(), its index.js executes an IIFE that performs extensive host reconnaissance: hostname, user identity, network configuration, environment variables filtered for API keys/tokens/secrets/n8n/docker credentials, listening ports, Docker socket access, mounts, cgroups, capabilities, process list, crontab, and n8n-related files. It then scans the Docker bridge subnet 172[.]17[.]0[.]0/24 on ports 80, 443, 8080, and 5678 for open containers. All collected data is exfiltrated via TCP to 103[.]27[.]109[.]184:8892. A reverse shell is also established to the same IP:port. The package's TaskRunnerNode.js is a decoy node class with an empty execute method. The C2 endpoint is 103[.]27[.]109[.]184:8892.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:06 PM
- analyzed
- Jul 17, 2026, 12:06 PM
Related advisories
- react-campaign-optimizer@1.0.0
- chalk-ultra@12.0.3
- kisama-js@0.1.8
- node-vfs-polyfill@2.0.5
- stellarfixer@1.0.0
- simple-date-formatter-util-12@1.0.0
- twork-data-services-customer-api-v2-customer-vip-status@20.9.7
- streak-int-lib@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.